
F5Certified Solution Expert, Security
Domain 3Objective 7
3.07 Verify a Configuration Is Functioning as Intended to Mitigate a Vulnerability 401 Practice Questions (Page 3)
Part of the OPERATION AND IMPLEMENTATION domain, which makes up ~38% of our current practice bank. F5 does not publish an official question count, but from its 105-minute exam (~40–70 total, ~15–27 in this domain), expect 2–4 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
6concepts
Questions 11–15
- 11
A security analyst notices an increase in requests to a web application that contain encoded characters. The ASM policy is configured to block encoded attacks. The analyst wants to verify the policy is actually blocking these requests. Which log review approach provides the most reliable confirmation?
Select an answer first - 12
Which action best validates that a configuration mitigates a specific vulnerability?
Select an answer first - 13
A security team deployed an ASM policy to mitigate a critical CVE. The policy is in blocking mode. After deployment, the team sends a proof-of-concept exploit and the ASM log shows a 'blocked' action. However, the application team reports that the exploit still reaches the backend. Which analysis best explains this discrepancy?
Select an answer first - 14
Which observation would confirm that a rate-limiting mitigation is working?
Select an answer first - 15
An administrator configured an iRule to redirect HTTP requests to HTTPS to mitigate a downgrade attack. After deployment, the administrator wants to verify the redirect is working. Which test provides the most conclusive evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by F5. “401” is a trademark of its owner, used for identification only.